25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Email Accounts Compromised in Atrium Health Phishing Attack
Sep16

Email Accounts Compromised in Atrium Health Phishing Attack

Charlotte, NC-based Atrium Health, a healthcare provider with 40 hospitals and more than 1,400 care locations in North Carolina, South Carolina, Georgia, and Alabama, has discovered unauthorized access to several employee email accounts. The unauthorized email account access was detected on April 29, 2024. Its email environment was secured, and a forensic investigation was conducted to determine the nature and scope of the unauthorized activity. The investigation confirmed that an unauthorized third party accessed a limited number of employee email accounts as a result of a phishing campaign. The phishing emails appeared to have been sent by a trusted source and several employees responded and inadvertently disclosed their account credentials, allowing their accounts to be accessed by an unauthorized individual for a short period between April 29 and April 30, 2024. The account review was completed on July 17, 2024, and confirmed that patients’ protected health information was present in the accounts. It was not possible to determine whether patient data was viewed or...

Read More
New York Health Insurer Must Repay $7.7M After Using Excluded Medicaid Provider
Sep16

New York Health Insurer Must Repay $7.7M After Using Excluded Medicaid Provider

A health insurer has been ordered to repay almost $7.7 million to the New York state Medicaid program after using a company run by a social worker who had lost his license and been excluded from the Medicaid program. The New York-based health insurance company Fidelis Care, a subsidiary of Centene Corp, administers managed health care plans available to residents of New York, including individuals enrolled in the New York State Medical Assistance Program (Medicaid). The Medicaid Managed Care/Family Health Plus/HIV Special Needs Plan/Health and Recovery Plan Model contract with the New York Department of Health requires Fidelis Care to ensure that providers used for Medicaid-reimbursed services and their owners are appropriately licensed to practice by the state and have not been excluded from the Medicaid program. The Medicaid Fraud Control Unit investigated Fidelis Care and determined that, from February 7, 2019, to July 30, 2021, Fidelis Care used a company called Cornerstone Herkimer LLC, whose sole owner and director was Ward Halverson. Ward Halverson had his license to...

Read More
FBI Issues Warning About BEC Attacks as Losses Increase to $55.5 Billion
Sep13

FBI Issues Warning About BEC Attacks as Losses Increase to $55.5 Billion

The Federal Bureau of Investigation (FBI) has issued a warning to businesses about business email compromise (BEC) scams, which have resulted in losses of almost $55.5 billion over the past decade. BEC is a sophisticated scam that targets businesses and individuals. While the aim of the scam may be to obtain sensitive information, these attacks are commonly conducted on individuals who perform legitimate transfer-of-funds requests and trick them into making fraudulent wire transfers. These attacks commonly start with phishing attempts with social engineering techniques used to compromise email accounts. Accounts may also be accessed using stolen credentials or through computer intrusions. Once access is gained to a suitable email account, emails are searched to find information that can be used in the scam.  The scammer may monitor the account for communications, hijack message threads and take over conversations, and copy the writing style of the account holder to make their requests more realistic. The account owner is impersonated, and emails are sent to individuals responsible...

Read More
Illinois Bone & Joint Institute Hacking Incident Affects 568,000 Patients
Sep13

Illinois Bone & Joint Institute Hacking Incident Affects 568,000 Patients

A data breach has been reported by the Illinois Bone & Joint Institute that affects more than 182,000 individuals. A network security incident has been reported by Access Sports Medicine & Orthopedics in New Hampshire that affects 88,044 individuals. Illinois Bone & Joint Institute The Illinois Bone & Joint Institute (IJBI), which operates over 100 clinics in the Chicagoland area, announced it detected unauthorized access to certain computer systems on July 4, 2024. Hackers first gained access to its network on May 30, 2024, and were ejected on July 4, 2024. IJBI said its facilities remained open throughout and care continued to be provided to patients. The forensic investigation confirmed that files were copied from its network, which included the information of patients and dependents of those individuals, including names, addresses, dates of birth, Social Security numbers, diagnosis and treatment information, and health insurance/claims information. No evidence has been found to indicate any misuse of the stolen data. Complimentary credit monitoring services have...

Read More
Goodwin Living and L.A. County Department of Mental Health Suffer Email Breaches
Sep13

Goodwin Living and L.A. County Department of Mental Health Suffer Email Breaches

Goodwin Living and the Los Angeles County Department of Mental Health have recently reported breaches of their email environments and the exposure and potential theft of patient data. Goodwin Living, Virginia Goodwin House Incorporated, which does business as Goodwin Living and provides hospice care, home health, and rehab services, has discovered unauthorized access to an employee email account. The forensic investigation confirmed unauthorized access to the account from October 2, 2023, to October 18, 2023. Following the investigation, the compromised account was manually reviewed to identify the individuals affected and the types of data involved, and that process was completed on July 30, 2024. The review confirmed that the account contained the protected health information of 7,170 patients, which an unauthorized third party may have viewed or acquired. The information involved varied from individual to individual and included first and last names combined with addresses, phone numbers, email addresses, dates of birth, Social Security numbers, driver’s license numbers,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist